I recently shared an update regarding the Think Node M9 from Elecrow, a device I tested in my recent Meshtastic update. Shortly after that video was posted, I received an email from the company stating that the device contains a virus and must be returned. While the virus is not active on the device itself, it presents a risk if its internal SD card is removed and inserted into a Windows computer. While they responded appropriately to the issue, they also requested that I not talk about this issue on my channel. That’s not cool.
The risk occurs when accessing the firmware on the SD card for updates. The malware identified is known as Sality. According to the Department of Justice, this malware turns an infected computer into a node on a peer-to-peer botnet. Once a computer is part of this network, it can be used for cryptocurrency theft or cyber attacks, often operating in the background without the user’s knowledge. Although the Department of Justice recently disrupted a significant portion of the Sality network, the presence of such software on a consumer device is a serious matter.

After sending the initial warning, Elecrow sent a follow-up email asking me not to discuss the situation publicly. Transparency is a necessary component of the relationship between manufacturers and the public, particularly as supply chain attacks become more frequent. These incidents often occur when companies utilize contract factories without maintaining rigorous quality control over the software and firmware being installed. If the factory’s duplication process is compromised, malware can be embedded into thousands of devices before they ever reach a consumer.
Elecrow is not the only manufacturer to face these challenges recently. Geekom, a producer of mini PCs, recently hosted an infected network driver on its website. The driver contained the Asruex malware, which is designed to steal credentials while remaining hidden from antivirus scanners. Like Elecrow, Geekom reportedly contacted the outlet that broke the story and requested its removal.
Similarly, the company Ace Magic shipped mini PCs with a backdoor known as win32 bladabindi embedded directly into the Windows recovery image. Reports indicated that AceMagic attempted to influence the narrative by offering incentives for the removal of negative reviews and requiring reviewers to submit content for approval prior to publication.
These hardware issues are part of a broader trend of supply chain vulnerabilities that extend into software. Attackers recently compromised the Notepad++ website to swap the official distribution with an infected version. In another instance, an open-source library called Axios was found to have an infected component. Because Axios is integrated into many other software packages, the malware spread to Windows, Linux, and Mac systems through standard updates from trusted sources.
Protecting a system in the age of AI requires a more proactive approach than ever before. Maintaining an up-to-date operating system and running frequent antivirus scans is essential, even when dealing with hardware or software from trusted hardware and software makers.
